oss-sec mailing list archives

Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz


From: Robert Watson <robertcwatson1 () gmail com>
Date: Mon, 17 Jun 2019 01:28:04 -0400

So Mr Gayner, which of these bugs have you fixed?

On Sat, Jun 15, 2019, 11:50 Alex Gaynor <alex.gaynor () gmail com> wrote:


Today I'd like to highlight what I see as a tremendous issue: very few of
these security bugs ever has a CVE issued for it. This is probably due to a
few factors, a) the relative difficulty of obtaining a CVE, b) the lack of
a human reporter who is interested in obtaining one for "credit" purposes,
c) the sheer number of bugs that we're talking about.




Current thread: